Junglewise Threat Intelligence

CVE-2026-33273: ICZ Corporation MATCHA INVOICE unrestricted file upload

CVE-2026-33273 · Severity: high · CVSS 7.2 · Published 2026-04-08

Executive brief

MATCHA INVOICE, an invoicing and billing management software, contains a security flaw that allows an administrative user to upload dangerous files to the server. If exploited, an attacker with administrative access could take full control of the server, potentially leading to the theft of sensitive financial data or a complete service shutdown. Organizations using version 2.6.6 or earlier should update to the latest version immediately to prevent unauthorized code execution.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in ICZ Corporation MATCHA INVOICE versions 2.6.6 and earlier. The flaw allows a remote attacker with administrative privileges to upload arbitrary PHP files to the server. Because the application fails to properly validate file types or restrict upload locations, the attacker can execute these files to achieve arbitrary code execution (RCE) and gain full system control. The vendor has released version 2.6.7 to address this issue.

Affected products

  • ICZ Corporation MATCHA INVOICE 2.6.6 and earlier

Timeline

  • 2026-04-07: patched: Vendor released version 2.6.7 to address the vulnerability.
  • 2026-04-08: disclosed: Initial disclosure via JVN and NVD.

References

Related threats